This in-depth report from Gartner explores how organizations can unlock the full value of SBOMs and greatly enhance software supply chain security, including:
Cyber-criminals today are increasingly targeting vulnerable open-source libraries in DevOps pipelines – as was the case in the infamous log4j incident. Software engineering teams often lack the tools, practices and standards to systematically discover and share details about vulnerable software packages across the organization.
Software bills of material (SBOMs) are a critical starting point for software supply chain security. According to Gartner, “SBOMs are an essential tool in your security and compliance toolbox. They help continuously verify software integrity and alert stakeholders to security vulnerabilities and policy violations.”
However, SBOMs alone are not enough. While SBOMs can tell you if a vulnerable library is being used in a piece of software, achieving software supply chain security at scale requires certain capabilities.
Gartner, Innovation Insight for SBOMs, 14 February 2022, Manjunath Bhat, et. Al.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission.
All rights reserved.